Outlook在中国遭中间人攻击
网络监测组织GreatFire于1月17日收到了报告,指微软电邮系统outlook在中国遭中间人攻击(MITM)。此次攻击针对通过移动设备上的邮件客户端收发outlook邮件的人士。该组织怀疑,此次攻击是审查部门在测试防火墙技术。
当中国用户通过电子邮件客户端(Ice-dove)进入outlook时,可看到以下证书:
Greatfire的测试证实了outlook确实遭到攻击:IMAP(交互邮件访问协议)与SMTP(简单邮件传输协议)都遭受了中间人攻击。但网站界面(https://outlook.com 和 https://login.live.com/)没有受到影响。这次攻击持续了大约一天,现在已经停止。
这种形式的攻击尤其狡猾:相比于通过浏览器,用户通过电子邮件客户端所接收到的警告非常不明显,更容易被忽略。如下图:
(从iphone默认电邮客户端接收到的错误样本)
当客户端试图自动检索信息时,用户只能看见一个突然弹出的警告。因为用户没有主动检索信息,大多数的用户在点击“继续”之前不会细想,却忽视了警告信息、或把警告信息归咎于网络连线的故障。如果用户真的点击了“继续”,他(她)所有的邮件、通讯录、密码都会被黑客所窃取。
这次黑客攻击发生在Gmail被封锁之后的一个月之内(Gmail到现在仍然处于完全无法使用状态)。由于这次中间人攻击与之前对谷歌、苹果、雅虎等的攻击存在诸多相似之处,Greatfire再次怀疑,中国国家互联网信息办公室精心策划了这次袭击,或者有意允许袭击发生。这就意味着中国当局有意进一步打击他们无法容易监控的通信手段。
至截稿为止,微软公司尚未对此事作出回应。
三个月前,针对苹果iCloud储存服务的中间人攻击促使苹果总裁库克亲自到中国与当局交涉。中国外交部新闻发言人随后否认了攻击,苹果也从未公开与中方的交涉结果。苹果后来创建了一个“中文帮助页面”来处理相似的问题,并将其称为“有组织的网络攻击”(organized network attacks)。
在苹果被攻击的同时,谷歌和雅虎也有经历类似的中间人攻击,微软outlook的网页版也曾在短时间内受攻击。当局似乎是在测试他们的中间人攻击技术,并搜集用户反应。通过追踪有多少用户忽视了警告信息,当局可以评估这类攻击的有效性。
GreatFire强烈建议用户,千万不要绕过证书提示的“错误信息”去点击“继续”。
呼吁停止信任CNNIC证书
GreatFire怀疑国家网信办对此次黑客攻击outlook、以及其他几起类似的攻击负有直接责任。由于中国互联网信息中心(CNNIC)的直接主管部门是国家网信办,它所认证的安全证书也因此不值得信任。
GreatFire再次呼吁互联网公司和相关组织,包括微软和苹果,立即停止将CNNIC作为认证机构(certification authority)的信任。
- CNNIC的证书有什么作用?
它可以用于初步地识别个人或设备的身份、鉴定服务、加密文件。
- 什么是认证机构(certification authority: CA)?
认证机构是颁发证书的机构。他们建立和验证了公共密钥的鉴定系统,以及核实请求密钥的个人或组织的身份。
Technical Details
IMAP/SMTP are commonly used on mobile email clients (e.g the default mail application on iPhones) and desktop email clients like Thunderbird. Internet Message Access Protocol (IMAP) is a protocol which allows users to connect to the same mailbox through multiple devices (i.e. your desktop, mobile, etc.). Simple Mail Transfer Protocol (SMTP) is typically used by users to send messages to a server which are then relayed to the recipient.
Wikipedia defines a man-in-the-middle (MITM) attack in the following way:
The man-in-the-middle attack...is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.
测试
为了在火狐浏览器中复制以上结果,我们首先在火狐中设置允许接入端口993,这也是IMAP所使用的端口。然后,我们登入https://imap-mail.outlook.com:993,立刻收到了警告信息。正如你在下图所看到的那样,这份证书是自我签名的(self-signed)。
下图可以看到Chrome中显示的证书错误。Chrome也被设置成允许通过端口993进行连接。
The fake certificate used in the attack:
WireCapture:
https://www.cloudshark.org/captures/8bf76336e67d
Reports:
https://www.v2ex.com/t/163062 and https://www.v2ex.com/t/163018.
评论
Removing CNNIC root isn't practical, as it prevents the company from selling devices in China. Please make more practical recommendations. For example, only accept CNNIC-signed certificates for .CN domains. That would allow CNNIC to continue to exercise control over Chinese domains without jeopardizing the security of the entire Internet. (This is basically "TLD pinning" for root CAs.)
happy rose day sms
happy Chocolate day sms
Happy Valentines Day status
happy kiss day sms
Romantic Getaways: You can also plan a romantic holiday with
your loved one. It is really nice to see all these valentine's
day gift ideas for dogs, cause you two will be hollering with
love don't you know. This need not always be romantic love but any love.
Review my site: Propose Day SMS
After Daytona Beach Police Detectives finished their investigation of the incident, the scene was turned over to a site manager for Clean
Fuels National, who police emphasized was not at the
scene when the incident happened. It has emerged as one of the
best weekend destinations especially for families.
The last four or five years there's been more of a mix of INDYCAR drivers going over, which
is good for both series.
Also visit my web site ... daytona 500 live streaming
this post is awesome, great msg for us, plz update ur blog for daily basis, i am regular visitor of this site, so keep posting for us,
click the below links to create backlink
best free backlink website click here for msg movie
nice
Ontips-in
wwe wrestlemania31 live stream
PPV WWE Wrestlemania 31 2015
wwe wrestlemania31 2015 live stream
thanks for this post, keep it up for updating us, i am waiting for ur new article.
thanks again
IPL8 live stream 2015
Thanks mate for share this nice post
WWE Wrestlemania 31 Live Stream
WWE Wrestlemania 31 Live Stream
Watch Game Of Thrones Season 5 Episodes
Watch Game Of Thrones Season 5 Episodes
Watch Avengers: Age of Ultron Movie Online
Watch Ted 2 Movie Online
Ipl 8 live score
Ipl 8 live streaming
It’s certainly fresh to writing and seeing concepts which are truly helpful to get the direction
mothers day quotes
happy mothers day qutes 2015
happy mothers day 2015
Nice post to share
http://listacademyanik.com/
Nice post to share.
CLICK HERE>>
http://www.100kfactoryultraeditionreview.com/
----------------------------------------
There many errors that can hurt your PPC project without you even understanding it. For this factor, I wish to present to you the leading 5 factors your Pay Per Click project suffers online. look at part 1 of this article
----------------------------------------
CHECKOUT>>www.100kfactoryultraeditionreview.com
--------------------------------------------------------------------------------
http://listacademyanik.com/
============================================
Hey,
"Good website! I really love how it is easy on my eyes and the data are well written. I am wondering how I could be notified when a new post has been made. I have subscribed to your RSS feed which must do the trick! Have a nice day!"
======================
CLICK HERE>>http://listacademyanik.com/
======================
It Was An Wonderful Post ! https://www.reddit.com/r/virtualceolifestyle
Hey ,
I would like to thank you for the efforts you have put in writing this website. I'm hoping the same high-grade web site post from you in the upcoming also. In fact your creative writing abilities has inspired me to get my own web site now. Actually the blogging is spreading its wings rapidly.
http://listacademyanik.com/dna-wealth-blueprint-3-0-review-bonus
good Study how to setup Kodi earlier known as noted as XBMC Kodi Download Linux, iOS, Windows, and Android. Moreover, Kodi App Android nice.
good The formal webpage of Droid4x packages a tiny method data file on Droid4x your laptop when you struck the ‘download&' button. nice.
good cannot send or receive messages or pictures utilizing it. snapchat sign in file from its web site and also run the installer as well as nice.
Download caller name announcer from callernameannouncer.uniqsofts.com to read al incoming notifications.
Thanks mate for share this nice post
obat pembesar penis klg: http://obatfrigid.com/obat-klg.html
Playstore in our android devices since long. Though Playstore is fairly aptoide apk you uninstall the app, simply click the apk once again and install
Game Guardian is an amazing game hack/alteration tool. Game guardian helps you modify money, HP, Sp and more aspects of the game.
game guardian apk
http://google.com
I definitely enjoyed every bit of it and I have you bookmarked to see new information on your blog.
my boy
A festival is an event ordinarily celebrated by a community and centering on some characteristic aspect of that community and its religion or traditions. It is often marked as a local or national holiday, mela, or eid.
http://festival-status.wallinside.com
For a lot of us looking to establish an online store, 'e-commerce' is where it all begins. When you find this phrase in articles and testimonials - it simply refers to the buying and selling of products on the internet.
To Get More Info>> https://www.7figurecyclereviewbonus.com/ << VISIT HERE
After reading the article I updated my knowledge regarding the same.
It really helped me a lot.
Thanks for sharing this with us.
https://www.kickstarter.com/profile/netgearsupport/about
At this rate, shouldn't China create their own operating system like what North Korea did? Everything is banned, it's so annoying for tourists. Thank you for sharing the news! I want to visit China some day but with this policy, I can't receive email from work when traveling, it's very hard for me.
https://htmlcolor-codes.com/
添加新评论